Free tool · Reg Advantage

What scrutiny should you expect from the FCA? This framework sets out how the FCA tests firms — at Part 4A authorisation and throughout ongoing supervision. Scope your firm in Part 1, then work through each domain in Part 2 to evidence and test your arrangements.

Use it if you are preparing a Part 4A application (including MLR-registered cryptoasset firms moving to full authorisation), or if you are already authorised and want a structured basis for compliance monitoring and testing.

Your answers are stored only in your own browser. Nothing is sent to Reg Advantage. General information only — not legal or regulatory advice.

Reusable template · Reg ADV
regadv.com
FCA regulatory review framework · Investment managers & cryptoasset firms

FCA regulatory review
Scoping engine & review workbench

Answer the scoping questions below. Determinations are set automatically and Part 2 domains update to show only the obligations that apply. Add findings, status and RAG ratings as you work through the review.

Reg Advantage Ltd · FCA regulatory review framework. Complete scoping answers in Part 1 to set scope; work through the domains in Part 2. A review template, not a compliance opinion — handbook references should be confirmed against the current FCA Handbook. © 2026 Reg Advantage Ltd (company no. 17304464).
Part 1 · Scoping engine — answer each question to set the applicable regulatory framework
Applies only to AIFM / CPMI / UCITS managers — masked N/A for MiFID-only firms and ARs. SMA / segregated mandates are MiFID business, excluded from AIFMD AUM: only count AIFs managed.
SNI thresholds: AUM < £1.2bn · COH < limits · ASA = 0 · CMH = 0 · B/S < £100m · gross revenue < £30m. Any firm with permission to deal as principal is automatically non-SNI.
Preceding year, per last annual accounts, after MIFIDPRU 4.5.3R deductions — exclude fully discretionary bonuses / LLP member profit shares, contingent shared commissions, profit taxes, non-recurring non-ordinary items; add back fixed costs borne by third parties. FOR = ¼ of this figure
Set by permissions (MIFIDPRU 4.4): £75k / £150k / £750k
ICARA — own-funds threshold requirement (OFTR) inputs
Identified via ICARA harms assessment, on top of OFR
Bottom-up ICARA estimate over a realistic horizon (often 3–6 months, reduced headcount) — must include crystallising costs: redundancy/notice, lease exit, contract termination, professional fees. OFTR floor remains the OFR
AIFMD own-funds layer (full-scope AIFM only)
Enter the full figure, not millions — e.g. 375000000 for €375m
€125k base + 0.02% of AIF AUM above €250m, capped at €10m — plus professional negligence cover: additional own funds of 0.01% of AIF AUM, or PII. Met in parallel with MIFIDPRU, not added to it. AIFs only — excludes SMA / segregated mandate AUM.
RTS 6 applies where trading parameters (timing, clip, risk mgmt) are set by algorithm with limited/no human intervention per order.
UK/EU domicile makes the fund itself an EMIR counterparty — the AIFM must ensure the fund's derivative reporting occurs. Agent execution capacity does not remove this.
Map each activity against the perimeter guidance (PS26/18) before relying on any exclusion. Lending / borrowing is not a separate activity but attracts specific rules in PS26/11.
Same evidential burden either way: pre-authorisation tests readiness to operate on submission; post-authorisation tests that the controls operate in practice.
Active determinations Regime — AIFMD — SNI — SMCR — Clients — Assets — RTS 6 — Crypto — MiFIR —
Show
Part 2 · Review domains

Obligation by obligation — questions and evidential burden

Domains update automatically as scoping answers change. Greyed domains are outside scope for the current determination; flagged domains carry a gap or enhancement note. Use the review panel in each domain to record status, RAG rating and findings.

Group A

Governance, people & oversight

01
Threshold conditions & senior-management arrangements
COND · PRIN · SYSC 4
In scope—›
Qualifying criteria
COND — ongoing satisfactionAll authorised firms
PRIN 2A (Consumer Duty)Gated on retail in distribution chain
SYSC 4 organisational requirementsAll firms
Review questions
  1. Does the firm continue to satisfy each threshold condition — effective supervision, appropriate resources, suitability, business model?
  2. Is the governing body composition, meeting cadence and decision record adequate, with minutes evidencing genuine challenge?
  3. Is apportionment of responsibility clear and unduplicated across principals and key functions?
  4. Is there a documented governance map showing committees, delegations and escalation routes?
Evidence to obtain & test
  • Regulatory business plan / firm profile and latest financial position.
  • Board / committee terms of reference and last 3–4 sets of minutes.
  • Governance / organisation chart and delegation schedule.
  • Board MI pack — confirm compliance, risk and prudential MI reaches the board.
02
SMCR — senior managers, certification, conduct & people framework
SUP 10C · COCON · FIT · SYSC 27
In scope—›
Qualifying criteria
SMCR tier (scoping Q5)Set by scoping
Core firm SMFs (as applicable to legal form and permissions)Typically SMF3 (or SMF27 in an LLP) · SMF16 · SMF17
Enhanced additional requirementsSee scoping Q5
Review questions
  1. Are all required SMFs held, with no prescribed responsibility unallocated or duplicated?
  2. Are Statements of Responsibilities drafted for each SMF, with prescribed responsibilities allocated?
  3. Is the certification population correctly identified (MRTs, client-dealing, algo-trading certified function) with annual F&P assessments?
  4. Is the conduct-rules training programme in place and evidenced for all staff?
  5. Are job descriptions, defined reporting lines, organisation chart and L&D / T&C plans documented for certified staff?
  6. Is there a JML process covering pre-hire screening, SYSC 22 regulatory references, onboarding attestations, role changes and exit references?
  7. Are policy attestations and training completion tracked and evidenced?
  8. Are the Enhanced-only requirements met: management responsibilities map, handover procedures, the full set of Enhanced prescribed responsibilities, and the overall-responsibility requirement?
  9. Crypto firms: SM&CR applies to authorised cryptoasset firms. Are the SMF holders identified early enough to be approved within the application (the SMFs required for the firm's SM&CR categorisation — noting stablecoin issuers become Enhanced at £20bn of backing assets, 3-year rolling average), with fitness-and-propriety evidence — including crypto-specific competence — ready for submission?
Evidence to obtain & test
  • FCA register extract per individual + regulatory references (SYSC 22).
  • Statements of Responsibilities and prescribed-responsibilities allocation grid.
  • Certification register and latest F&P assessments; MRT identification rationale.
  • Conduct-rules training records and attestation / policy-acknowledgement log.
  • Job descriptions, org chart, reporting lines; L&D / T&C plans.
  • JML procedure and sample joiner and leaver file tested end to end.
  • Management responsibilities map; handover procedures; overall-responsibility allocation.
  • Proposed SMF population, draft SoRs and Form A packs for inclusion with the Part 4A application.
03
Compliance function & oversight
SYSC 6.1 · SMF16 · CMP
In scope—›
Qualifying criteria
SYSC 6.1 — permanent, effective, independent compliance functionAll firms
Review questions
  1. Is there a documented, risk-based Compliance Monitoring Plan mapped to the firm's activities?
  2. Is there a breaches, errors and complaints register, with evidence it is used, escalated and closed?
  3. Where compliance functions are outsourced or consultant-supported, is the SMF 16 ownership boundary clean?
  4. Is there an annual compliance report to the board and a live regulatory action plan?
  5. Does compliance have genuine independence and unfettered board access?
Evidence to obtain & test
  • Compliance Monitoring Plan and completed monitoring / testing files.
  • Breaches & errors register; sample a closed item end to end.
  • Consultant engagement scope vs SMF 16 ownership.
  • Last annual compliance report and regulatory action plan.
04
Risk management & internal controls
SYSC 7 · FUND 3.7 (AIFM)
In scope—›
Qualifying criteria
SYSC 7 risk controlAll firms
FUND 3.7 — AIFM permanent risk function, separated from PMFull-scope AIFM only
Review questions
  1. Is there a documented risk appetite and risk register (market, counterparty, liquidity, operational, regulatory)?
  2. Is the AIFM risk-management function functionally and hierarchically separated from portfolio management (FUND 3.7), evidenced in the firm's structure?
  3. How is leverage measured and monitored, and against what board-approved limits?
  4. Are early-warning indicators defined and monitored, feeding the ICARA and board MI?
Evidence to obtain & test
  • Risk-management policy and (for AIFMs) evidence of functional separation.
  • Risk register and risk-appetite statement.
  • Leverage / exposure monitoring (gross and commitment method for AIFMs).
  • EWI dashboard and escalation evidence.
Group B

Prudential & remuneration

05
Prudential — own funds, ICARA, wind-down, liquidity, RegData
MIFIDPRU · AIFMD own-funds · RegData
In scope—›
Qualifying criteria
FOR = ¼ of the preceding year's relevant expenditure — total expenditure per last annual accounts less MIFIDPRU 4.5.3R deductions (fully discretionary bonuses / LLP member profit shares etc.) (MIFIDPRU 4.5.1R); basic liquid assets = ⅓ of FOR (MIFIDPRU 6.2.1R)All MiFIDPRU firms
K-factorsNon-SNI only
AIFMD own-funds layerFull-scope AIFM only — on fund launch
RegData (MIF001/002/007, Annex IV)All firms (SNI files simplified set)
Own-funds calculation (scoping engine inputs)
Complete the own-funds inputs in Part 1 (Q4) to see the calculated floors here.
Review questions
  1. What is the current own-funds requirement — which binds: PMR or FOR?
  2. What is the K-factor requirement, and does it exceed the FOR / PMR floor?
  3. On fund launch, is the AIFMD own-funds layer (base €125k + 0.02% of AIF AUM over €250m, cap €10m) and professional-liability cover (PII or additional own funds — 0.01% of AIF AUM) modelled?
  4. Is there a completed ICARA with harm identification, own-funds and liquidity adequacy, stress testing and a wind-down trigger — with the threshold requirement carrying wind-down costs?
  5. Is there a credible, costed wind-down plan with a defined trigger, timeline and resource, board-approved annually?
  6. Are RegData returns mapped, owned and submitted on time via Connect?
  7. Is the basic liquid-assets requirement calculated and held (⅓ of FOR), with EWIs set below regulatory minima?
Evidence to obtain & test
  • Own-funds calculation (MIFIDPRU, and AIFMD on fund launch).
  • ICARA document and supporting stress-test work; wind-down cost model.
  • Wind-down plan with trigger, timeline and cost.
  • RegData submission history; test a return against source.
  • K-factor calculations and supporting data governance.
06
Remuneration
SYSC 19B (AIFM code) · SYSC 19G (MIFIDPRU code)
In scope—›
Qualifying criteria
CPMI / full-scope AIFM → AIFM Remuneration Code (SYSC 19B) governs firm-wide, including MiFID businessCPMI / AIFM only
MiFID-only firms → MIFIDPRU Remuneration Code (SYSC 19G)MiFID-only firms
Review questions
  1. Is there a remuneration policy applying the correct code firm-wide, with proportionality reasoned and documented?
  2. Is the identified-staff (MRT) population determined and documented, with annual disclosure prepared?
  3. Are the pay-out process rules (deferral, instruments, malus/clawback) applied or disapplied on a documented proportionality basis, tested against FCA guidance on the AUM thresholds above which disapplication is less likely reasonable?
Evidence to obtain & test
  • Remuneration policy and identified-staff list with rationale.
  • Proportionality assessment referenced to FCA guidance thresholds.
  • Annual identified-staff disclosure.
Group C

Conduct & conflicts

07
Conflicts, side-by-side management & research
SYSC 10 · COBS 11.7A · COBS 2.3 · allocation
In scope—›
Qualifying criteria
SYSC 10 — all firmsIn scope
Side-by-side allocation — multiple mandates / fund + SMAWhere applicable
Research policy — non-cash inducementsAll MiFID firms
Review questions
  1. Is there a conflicts register and policy, kept current?
  2. Where multiple mandates (or a fund alongside SMAs) run the same strategy, is there a documented, testable trade-allocation and aggregation policy ensuring fair treatment?
  3. Is there a research policy determining treatment of paid vs unpaid research and non-cash inducements, with onboarding, notification and approval steps for research providers and expert networks, plus staff training?
  4. How are gifts, entertainment and inducements logged and controlled?
  5. Is personal-account dealing pre-cleared and monitored against firm positions and restricted lists?
Evidence to obtain & test
  • Conflicts register & policy; allocation policy.
  • Allocation records — sample a day's fills across mandates.
  • Research policy and register of approved providers (paid / unpaid).
  • G&E log; expert-call clearance log; PA-dealing pre-clearance records.
08
Market abuse, MNPI & surveillance
UK MAR · SYSC 6.1 · STOR
In scope—›
Qualifying criteria
UK MAR — all firms trading in-scope instrumentsIn scope
STOR obligationIn scope
Review questions
  1. How is inside information / MNPI identified, wall-crossed, recorded and controlled, with documented information barriers across strategies where needed?
  2. Is trade surveillance operating against defined scenarios (insider dealing, manipulation, layering), with alerts reviewed and dispositioned?
  3. Is communications surveillance operating across approved channels, with off-channel comms controlled?
  4. Is there a STOR identification and filing process, with decisions evidenced (including decisions not to file)?
  5. Are insider / restricted & watch lists maintained and reconciled to actual positions?
Evidence to obtain & test
  • MAR / market-abuse policy; MNPI policy.
  • Trade-surveillance configuration (scenarios, thresholds) and sample reviewed alerts.
  • Comms-surveillance coverage and lexicon; off-channel attestations.
  • Restricted / watch lists and STOR decision log.
09
Best execution & order handling
COBS 11.2A / 11.3
In scope—›
Qualifying criteria
Discretionary portfolio management → best-execution dutiesIn scope
Review questions
  1. Is there an order-execution policy identifying execution factors, venues and brokers, reviewed at least annually?
  2. Crypto dealing / platform: are there effective overarching execution arrangements (PS26/11) — multiple venues used for price checks, periodic monitoring and post-trade analysis — rather than transaction-by-transaction checks, with spreads and fees disclosed?
  3. Is execution quality monitored on an ongoing basis and evidenced?
  4. How are broker relationships assessed for execution quality and conflicts?
Evidence to obtain & test
  • Order-execution policy and last annual review.
  • Execution-monitoring MI and outlier investigations.
  • Broker / venue review records.
  • Crypto order-handling / execution policy and price-sourcing methodology.
10
Client agreements, categorisation & financial promotions
COBS 3 · 4 · 8A · s.21 FSMA · PROD
In scope—›
Qualifying criteria
COBS 3 categorisationAll MiFID firms
PROD 3 product governanceWhere retail in distribution chain
Review questions
  1. Is client categorisation performed and recorded for each client, with the professional basis (and any opt-up) evidenced?
  2. Is there an IMA / SMA agreement framework meeting COBS 8A content requirements?
  3. Is there a financial-promotions policy with a sign-off process and promotions register?
  4. Is PROD 3 product governance scoped, with target-market and fair-value assessments?
  5. Are Consumer Duty (PRIN 2A) obligations mapped across the distribution chain?
  6. Cryptoasset financial promotions: are promotions to UK consumers compliant with the crypto promotions regime in force since October 2023 — prescribed risk warnings, 24-hour cooling-off for first-time investors, client categorisation and appropriateness assessment, and no incentives to invest? Who approves promotions today (in-house as a registered/authorised firm, or an s.21 approver), and how does that change on authorisation?
Evidence to obtain & test
  • Client-categorisation records; IMA / SMA templates.
  • Financial-promotions policy and approval log; sample approved pitchbook.
  • PROD / target-market documentation; Consumer Duty assessments.
  • Crypto promotions sign-off log; risk-warning, cooling-off and appropriateness-test evidence.
21
Client assets (CASS) — scoping & documented rationale
CASS 1 · 6 · 7 · 8 · "controlling not holding"
In scope—›
Qualifying criteria
Does the firm hold or control client money or safeguard client assets?Determine and document — the scoping itself is the deliverable
CASS 8 — mandates (authority to control client money/assets held elsewhere)Determine per firm
Review questions
  1. Is there a written CASS scoping / non-application note evidencing the end-to-end flow — where client money and assets actually sit (client's own custodian / prime broker / fund depositary), and why the firm neither holds nor controls them at any point in the chain?
  2. Does the note expressly address the "controlling not holding" challenge — the argument sometimes raised that exercising discretionary portfolio management under an IMA amounts to controlling client money? The firm should be able to show its trading authority extends only to executing investment decisions within the mandate, and cannot direct money to itself or third parties.
  3. Are CASS 8 mandates checked — does the firm hold any authority (e.g. direct debit, power of attorney, standing authority over an account) that lets it control client money or assets held elsewhere? If so, CASS 8 record-keeping and controls apply even where CASS 6/7 do not.
  4. Is there a control for incidental receipt of client money (e.g. a client payment landing in the firm's account in error) — identification, prompt return, and record?
  5. Is the CASS classification (including "no permission to hold client money") consistent across the Part 4A permission, the IMA terms, and the compliance manual — with an annual re-verification checkpoint?
  6. Crypto safeguarding: where the firm safeguards cryptoassets for clients, the "no client assets" rationale above does not apply. The review shifts to CASS 17 (and CASS 7 for client money arising in connection with safeguarding) — see Domain 28.
Evidence to obtain & test
  • Written CASS scoping note — reasoned, end-to-end, addressing the controlling-not-holding point.
  • Flow-of-funds map — subscription, custody, trading, fees, redemption.
  • IMA clauses on authority, custody and payment instructions — verify no self-direction power.
  • CASS 8 mandate check and register (or nil return with rationale).
  • Incidental-receipt procedure and any incident records.
22
Consumer Duty & client categorisation — rationale & opt-ups
PRIN 2A · COBS 3 · elective professional tests
In scope—›
Qualifying criteria
Consumer Duty applies to firms in a retail distribution chain — disapplication for professional-only business must be reasoned, not assumedDocumented rationale required either way
Elective professional (opt-up) — COBS 3.5 quantitative and qualitative testsWhere any opted-up clients exist
Review questions
  1. Is there a documented Consumer Duty applicability assessment — identifying whether any product or service sits in a retail distribution chain (including indirect distribution), and recording the reasoned basis where the Duty is disapplied?
  2. Is the disapplication rationale kept under review — re-triggered by any new product, client type, distribution channel or fund launch (a retail-available UCITS would reverse it)?
  3. For each client categorised per-se professional, is the evidential basis on file (regulated status, balance-sheet / large-undertaking test, institutional character)?
  4. For any elective professional (opt-up), are the COBS 3.5 tests evidenced — the qualitative assessment (expertise, experience, knowledge) and the quantitative criteria — with the client's written request, the firm's warning, and the client's acknowledgement all retained?
  5. Where no opt-ups are accepted, is that stated as policy (professional-only, minimum allocation above the retail threshold) so the position is deliberate rather than accidental?
  6. Where suitability obligations attach (discretionary management), is the suitability assessment and its periodic refresh evidenced per client, proportionate to the professional categorisation?
  7. Crypto — retail customers: the Consumer Duty applies in full. Are products and services mapped for price and value, target market, consumer understanding and support — with outcomes monitoring and board reporting designed before the application, not after?
Evidence to obtain & test
  • Consumer Duty applicability assessment and board / SMF sign-off.
  • Client categorisation file per client — per-se evidence or full opt-up pack.
  • Categorisation policy — including minimum-allocation threshold and opt-up stance.
  • Suitability assessments and refresh records for discretionary clients.
  • Trigger log — evidence the rationale is revisited on new products / clients / channels.
  • Consumer Duty implementation plan for crypto products — fair-value assessments and outcomes MI.
Group D

Markets, trading obligations & reporting

11
Markets & trading obligations
MiFID transparency · position limits · clearing / DTO · RTS 6
In scope—›
Qualifying criteria
Pre/post-trade transparency — off-venue (OTC) tradingSet by scoping
Commodity-derivative position limits (MiFID)Set by scoping
Mandatory clearing & DTOVerify per instruments traded
RTS 6 algorithmic tradingSet by scoping Q8
Review questions
  1. RTS 6: Is there documented governance, pre- and post-deployment testing, kill-switch functionality and an annual self-assessment for algorithmic trading systems?
  2. Are algorithm development and testing environments segregated from production?
  3. HFT additional: Is there a conformance-testing record per venue, with market-making obligations (where applicable) documented?
  4. Is any trading conducted off-venue (OTC)? If so, are pre/post-trade transparency obligations met or delegated to the executing broker?
  5. Are position limits monitored — venue-set limits for the instruments traded, and any FCA-set limits on critical commodity derivative contracts (or competent-authority limits on EU venues)?
  6. Commodity-derivative position limits: Are MiFID position limits determined and monitored for each commodity-derivative instrument, with limit-breach escalation?
  7. Do any instruments fall under mandatory central clearing or the derivatives trading obligation? If so, confirm compliance and document the basis.
  8. Principal / prop capacity: Are own-account positions correctly identified, and is there a pre-trade risk / controls framework in place?
Evidence to obtain & test
  • RTS 6 self-assessment; algo governance policy; kill-switch documentation; test records.
  • Venue / OTC map confirming on-venue vs OTC execution and transparency treatment.
  • Position-limit monitoring approach; instrument-level check for regulator-set limits.
  • Commodity position-limit reports and breach log.
  • Clearing / DTO applicability note for the instruments traded.
  • Pre-trade risk controls and own-account position reporting.
12
Trade & position reporting
EMIR · UK SSR · DTR · MiFIR · REMIT
In scope—›
Qualifying criteria
MiFIR Art 26 transaction reportingSet by scoping (CPMI/AIFM exempt — verify)
EMIR — derivative counterparty; principal vs agentWhere principal in derivatives
UK SSR — net short positions (equities / sovereign debt)Where short selling in scope assets
DTR — major-holding notifications (long exposure, incl. financial instruments)Where equity thresholds crossed
REMIT — reporting requires an EU nexus; UK-only trading out of scopeSet by scoping (asset class)
Review questions
  1. MiFIR: Are Art 26 transaction reports being made on time via an ARM, with LEI, instrument, and execution venue data correct? Is there an exception report and reconciliation process?
  2. MiFIR exemption: Is the basis for the MiFIR exemption documented (CPMI / AIFM / agent-only)? Confirm the top-up permissions do not pull discretionary SMA business into scope.
  3. Is the firm's EMIR counterparty classification (FC / NFC) confirmed and documented?
  4. EMIR clearing thresholds: are they determined and monitored? An FC above the clearing threshold (FC+) is subject to the clearing obligation for in-scope OTC derivatives; below it (FC−) it is exempt from clearing. Both remain subject to reporting and risk mitigation (timely confirmation, portfolio reconciliation, dispute resolution) and, where the AANA threshold is exceeded, bilateral margin on uncleared derivatives. The classification must be calculated and actively tracked.
  5. Is EMIR derivative reporting operating (typically delegated to PB), with the delegation documented and reconciled to the trade repository?
  6. Fund as EMIR counterparty: the UK/EU-domiciled fund is itself an EMIR counterparty, and the manager (as AIFM) is responsible for ensuring the fund's derivative reporting occurs — agent execution capacity does not remove this. Is fund-level EMIR reporting mapped, delegated (PB / administrator) by written agreement, and reconciled to the trade repository?
  7. Are UK and EU SSR net short position notifications identified and filed on time via the FCA / competent authority portal?
  8. Are DTR major-holding notifications monitored and filed on time, including aggregation across funds and mandates?
  9. REMIT: REMIT reporting is not required for UK trading by entities trading in the UK — an EU nexus (EU wholesale energy products / delivery in the EU) brings reporting into scope. Is the EU-nexus analysis documented, and where in scope, is the firm registered as a market participant with reports filed via an RRM?
Evidence to obtain & test
  • MiFIR scope memo (in or exempt) and, if in scope, transaction reporting reconciliation.
  • EMIR classification (FC/NFC) and clearing-threshold monitoring; delegated-reporting agreement and TR reconciliation.
  • SSR notification log and position-monitoring tool.
  • DTR major-holding monitoring and filing log.
  • REMIT registration confirmation and filing log.
13
AIFM operating obligations & delegation oversight
FUND 3 · valuation · liquidity · delegation · Annex IV
If AIFM—›
Qualifying criteria
Full-scope AIFM (Det. 2) → FUND 3 in fullIn scope on fund launch
Delegation of PM / sub-advisoryOversight in scope
Annex IV reportingIn scope (AIFM)
Review questions
  1. Are valuation (FUND 3.9) and liquidity-management (FUND 3.6) arrangements documented, with valuation independent of portfolio management?
  2. Where the firm delegates PM to a sub-adviser or is itself delegated from a ManCo, is the delegation chain and delegate oversight documented and monitored? Does the firm retain substance and not become a letterbox?
  3. Is Annex IV reporting mapped, tested and filed on the correct cadence?
  4. On fund launch: is a depositary appointed, with oversight duties understood and fund documentation finalised?
Evidence to obtain & test
  • Valuation & liquidity-management policies.
  • Delegation agreements & delegate-oversight / DD files.
  • Annex IV filing and reconciliation to source.
  • Fund documentation suite and depositary appointment.
14
Fund marketing & cross-border distribution
AIFM Regs 2013 · UK NPPR · s.238 · EU AIFMD marketing · US (SEC IA / CFTC CPO)
If fund—›
Qualifying criteria
UK marketing — FCA notification under the AIFM Regulations 2013 (UK AIF) or UK NPPR (non-UK AIF); s.238 FSMA restrictions on promoting unregulated schemes to non-professionalsOn fund launch
EU distribution — AIFMD NPPR / marketing passportIf EU investors
US distribution — SEC IA / CFTC CPO / NFA; non-US exemptionsIf US investor outreach
Review questions
  1. Which jurisdictions will the fund be marketed into, and to which investor types? Map the outreach before scoping obligations.
  2. For EU investors: is the AIF marketed under national private placement regimes (NPPR / Art 42) with registrations in place? Are pre-marketing rules observed?
  3. For US investors: which exemptions are relied on — SEC private-adviser / de minimis, CFTC exemptions (e.g. 4.13(a)(3))? Are the exemption conditions met and documented?
  4. For APAC investors: is the applicable regime identified per jurisdiction — e.g. Singapore (SFA s.304 / s.305 exemptions — institutional / accredited investors, restricted-scheme notification), Hong Kong (SFC professional-investor exemption), Japan (FIEA QII private placement), Australia (wholesale-client exemption) — with conditions met and any local filings made?
  5. Is a marketing-approvals process in place so materials are reviewed against the applicable regime before use?
Evidence to obtain & test
  • Distribution plan / investor-outreach map by jurisdiction and type.
  • NPPR / passport registrations and pre-marketing records.
  • US exemption analysis (SEC IA / CFTC CPO) tied to actual outreach.
  • Marketing-approval log.
23
Fund documentation, terms & operation
PPM / prospectus · depositary · directors · IMA · valuation
Conditional — set scoping—›
Qualifying criteria
Applies where a pooled fund vehicle exists or is being launchedGated on scoping Q10
Review questions
  1. Fund governance: is the fund board appropriately constituted — independent directors where market practice or domicile requires, meeting cadence, conflicts management between fund board and manager, and D&O cover in place?
  2. Depositary: is the depositary appointed with the agreement covering safekeeping, cash-flow monitoring and oversight duties — and is the manager's interaction with depositary oversight (breach reporting, verification requests) defined and operating?
  3. Independent risk and valuation: is the valuation function independent of portfolio management (internal with functional separation, or external valuer), with a valuation policy covering methodology, frequency, hard-to-value assets and error handling? Is the risk function's independence from PM similarly evidenced at fund level?
  4. PPM / prospectus mapped to reality: do the offering documents' investment objective, strategy, restrictions, leverage limits and risk factors map to the actual portfolio composition — with investment-restriction monitoring (pre- and post-trade) evidencing ongoing consistency, and a process for updating disclosure when the strategy evolves?
  5. IMA / management agreement terms: are the appointment terms between the fund and the manager complete and current — scope of discretion, fees and expense allocation, indemnities, termination, delegation rights — and consistent with the PPM disclosure?
  6. Side letters and investor terms: is there a side-letter register, with MFN obligations tracked and preferential-treatment disclosure (AIFMD) made where required?
  7. Fund operations: are administrator NAV production, pricing-error thresholds, subscription/redemption mechanics (including any gates, locks or notice periods) operating as documented, and reconciled to the offering terms?
Evidence to obtain & test
  • PPM / prospectus and any supplements; map disclosed restrictions to the live portfolio and the restriction-monitoring configuration.
  • Depositary agreement and recent oversight correspondence / breach log.
  • Valuation policy; valuer appointment or functional-separation evidence; a sample NAV pack.
  • Fund board minutes and director appointments; D&O policy.
  • IMA between fund and manager; fee / expense allocation policy.
  • Side-letter register and MFN / disclosure records.
Group E

Financial crime, operations & technology

15
Financial crime — AML/CTF, sanctions, ABC, tax evasion
MLR 2017 · SYSC 6.3 · FCG · SMF17 · Bribery Act · CFA 2017
In scope—›
Qualifying criteria
MLR 2017 — firm in scope; MLRO required (SMF17)In scope
Firm-wide AML risk assessment; CDD/EDD; SARs; sanctions; PEPsIn scope
Bribery Act (ABC) · CFA 2017 (tax-evasion facilitation)In scope
Review questions
  1. Is there a current firm-wide AML/CTF risk assessment, and does the AML framework flow from it?
  2. Is CDD/EDD operating for clients and material vendors? Are fund-investor KYC arrangements (via administrator) subject to defined oversight?
  3. Is sanctions screening automated and current, with a clear escalation and OFSI reporting route?
  4. Is the SAR/STR process to the NCA understood and evidenced, and is the annual MLRO report to the board produced?
  5. Are the ABC policy and Bribery Act reasonable-prevention procedures in place, and CFA 2017 prevention procedures documented?
Evidence to obtain & test
  • Firm-wide AML risk assessment; AML policy & procedures.
  • Sample CDD files (a client and a vendor) tested end to end.
  • Sanctions-screening configuration and a screening record.
  • SAR log / decision record; last MLRO annual report.
  • ABC policy; CFA prevention-procedures document.
16
Outsourcing, operational resilience, BCP, cyber & data
SYSC 8 · SYSC 4 · SYSC 15A (Enhanced) · UK GDPR
In scope—›
Qualifying criteria
SYSC 8 material-outsourcing governanceAll firms
SYSC 15A operational resilienceEnhanced-scope firms only
UK GDPR / DPA 2018All firms
Review questions
  1. Is there a material-outsourcing register and DD / oversight file for each critical provider?
  2. Is there a BCP proportionate to the firm, tested at least annually?
  3. Under SYSC 15A: are important business services identified, impact tolerances set and tested, and a self-assessment produced annually?
  4. Are cyber-security controls in place and reviewed, with a data-retention policy meeting record-keeping requirements?
  5. Is UK GDPR compliance addressed (ROPA, privacy notices, breach process)?
Evidence to obtain & test
  • Outsourcing register & DD files; exit / step-in considerations for critical providers.
  • BCP and last test record.
  • Cyber-security policy / assessment; data-retention policy.
  • SYSC 15A self-assessment and impact-tolerance testing evidence.
  • GDPR documentation.
17
AI governance
SYSC 4 / 6 · FCA AI approach
In scope—›
Qualifying criteria
No dedicated AI sourcebook — governed through SYSC and existing outcomes-based rules (SMCR, Consumer Duty, PRIN)All firms using AI tools
FCA position (2026)
  • The FCA regulates AI through existing frameworks (SMCR, Consumer Duty, SYSC) — technology-agnostic, outcomes-based; no AI-specific rules currently planned.
  • The FCA's AI Lab, Supercharged Sandbox and AI Live Testing (with Advai) are operating through 2026 (second cohort from April 2026; evaluation Q1 2027).
  • January 2026: FCA launched a retail-AI review; "good and poor practice" publication expected. FCA emphasises evidenced AI governance, senior-manager ownership, and customer outcomes / market integrity as AI systems scale in autonomy.
Review questions
  1. Is there an AI policy framework covering acceptable use, human oversight, data handling and third-party AI tools?
  2. Is there an inventory of AI/ML use across the firm, with senior-manager ownership identified for each material use?
  3. How is confidentiality / MNPI handled where AI tools ingest firm or client data? Does the AI policy interlock with the information-barrier, data-retention and cyber policies?
  4. Is software / IT and AI-tool approval governance in place, without unnecessary friction on legitimate tooling?
Evidence to obtain & test
  • AI policy / acceptable-use framework.
  • AI-tool inventory and vendor due diligence.
  • Policy interlock with information-barrier, data-retention and cyber policies.
18
Legal & commercial risk
vendors · contracts · HR · IP · lease · data · change control
In scope—›
Qualifying criteria
Operational / legal risks capable of causing regulatory or business harmAll firms
Review questions
  1. Is there a contracts register and review process for material agreements (PB/ISDA, IMAs, service agreements, market-data / alt-data licences)?
  2. Is there a vendor-onboarding DD and approval process feeding the outsourcing register?
  3. Is there a change / new-business acceptance process so that opening a new market, product, client type or jurisdiction triggers DD and sign-off before go-live?
  4. Are employment / HR arrangements sound — contracts, restrictive covenants, garden leave, immigration / sponsorship?
  5. Are premises / lease, insurance (PII, D&O, cyber), IP ownership (proprietary tooling and models) and GDPR arrangements in order?
Evidence to obtain & test
  • Contracts register and key agreements (PB/ISDA, IMAs, market-data licences).
  • Vendor-onboarding DD and approval records.
  • Change / new-business acceptance procedure and a sample decision.
  • Employment contracts, IP assignments, insurance schedule, lease, GDPR pack.
24
Legal entity & Companies House compliance
CA 2006 / LLPA 2000 · PSC · confirmation statements · accounts
In scope—›
Qualifying criteria
Entity form (scoping Q12) drives constitutional requirementsSet by scoping Q12
Review questions
  1. Are Companies House filings current and accurate — registered office, directors / members, PSC register, confirmation statement, accounts filed within deadline — and consistent with the FCA register entries?
  2. Is the statutory-books maintenance assigned to an owner (registers of members/directors, PSC, charges), with a filing calendar?
  3. LLP-specific: is there a current, executed members' agreement covering profit sharing, capital, decision-making, admission and retirement of members, and exit / repayment terms — and are at least two designated members appointed with their statutory duties (accounts, filings) understood?
  4. LLP capital and drawings: is members' capital treatment consistent with the regulatory capital position (own funds composed of members' capital meeting the permanence conditions), and are drawings policies compatible with maintaining the own-funds floor?
  5. Salaried members rules: has the employment-status analysis (Conditions A–C) been performed for fixed-profit members, with the outcome documented?
  6. Ltd-specific: are share capital, shareholder agreements and any share-class rights consistent with the controllers notified to the FCA (SUP 11), and is dividend / distribution practice compatible with maintaining own funds above threshold?
  7. Do any changes in members / directors / control cross FCA notification or change-in-control thresholds — and is the Companies House event linked to the FCA notification process so the two registers never diverge?
Evidence to obtain & test
  • Companies House extract reconciled to the FCA register and internal records.
  • Filing calendar — confirmation statement, accounts, event-driven filings.
  • Members' agreement; designated-member appointments; salaried-member analysis.
  • Articles / shareholders' agreement; controller analysis vs SUP 11 notifications.
  • Statutory registers including PSC.
Group F

Supervision & redress

19
Supervision, notifications & register accuracy
SUP 15 · SUP 11 · Principle 11 · Connect
In scope—›
Qualifying criteria
SUP 15 / Principle 11 — notification obligationsAll authorised firms
Register accuracy and Connect maintenanceAll authorised firms
Review questions
  1. Is there a notification framework so that reportable events (Principle 11 / SUP 15) are recognised and filed promptly via Connect?
  2. Are controllers and close links correctly recorded, and change-in-control processes understood?
  3. Is the FCA register data current and accurate — address, contact details, SMF appointments, permissions?
Evidence to obtain & test
  • Notification log / framework; any recent Principle 11 notifications.
  • Controllers & close-links record.
  • Register extract — verify accuracy across all fields.
20
Complaints & redress
DISP · eligible complainants · FOS
In scope—›
Qualifying criteria
DISP applies where there are eligible complainantsGated on client type
Review questions
  1. Is there a complaints-handling procedure, with the eligible-complainant analysis correctly scoping the obligations?
  2. If retail clients are in scope: is the full DISP framework operational, with FOS jurisdiction understood and a complaints MI pack produced for the board?
Evidence to obtain & test
  • Complaints policy & register.
  • Eligible-complainant analysis.
  • DISP / FOS procedures and complaints MI.
Group G

Cryptoasset firms — authorisation & ongoing compliance

Built from the FCA's final rules published 30 June 2026 (PS26/9 A&D and MARC; PS26/10 stablecoin issuance; PS26/11 regulated cryptoasset activities; PS26/12 prudential; PS26/13 application of the Handbook, with FG26/5 Consumer Duty, FG26/6 operational resilience and FG26/7 international firms) and the perimeter guidance PS26/18. Areas still under FCA consultation — resolution, Financial Crime Guide updates, DeFi, audit requirements, regulatory-reporting supplementary questions — are flagged rather than stated.

25
Authorisation, perimeter & transition
SI 2026/102 · PS26/18 · FCA gateway direction · FG26/7
Conditional — set scoping—›
Qualifying criteria
Firm carries on, or will carry on, a regulated cryptoasset activity by way of business in the UKGated on Q1 = cryptoasset firm
Application window (to rely on the saving provision)30 September 2026 – 28 February 2027
Regime commencement25 October 2027
Existing MLR registration, PSR/EMR authorisation or s.21 approver arrangementNone converts — authorisation or VoP required for in-scope activities
Timing — the three positions at commencement
  • Saving provision — applied inside the window and not yet determined on 25 October 2027: the firm may continue its specified activities, including new business, until the application is finally determined (subject to the statutory conditions).
  • Transitional (run-off) provision — applied after the window but before commencement and still pending, or refused / withdrawn: activity limited to performing pre-existing contracts, no new business, for up to two years. The firm must notify the FCA when it starts and stops relying on it, and tell counterparties to pre-existing contracts that it is not authorised, including any change to asset protection, dispute resolution or compensation.
  • No application — no access to either provision: UK business must be run off before 25 October 2027. An application rejected for missing minimum information is not a valid application.
Review questions
  1. Is every current and planned activity mapped against the nine regulated activities and the perimeter guidance (PS26/18) — direct permission, additional permission, or exclusion — with the reasoning documented?
  2. Is the application route correct: new Part 4A authorisation, variation of permission for an existing FSMA firm, or a UK establishment decision for an overseas firm (FG26/7)?
  3. Is the firm's position at commencement known — saving provision, transitional run-off or exit — and is the business plan consistent with it?
  4. Does the firm continue to satisfy the Threshold Conditions — including UK substance, effective supervision (group structure and close links), appropriate resources, suitability and business model?
  5. Is there a plan to file a complete, valid application inside the window, working back from 28 February 2027, with an owner for each component?
  6. Is there a board-approved regulatory business plan that reconciles business model, projections, prudential resources, staffing and controls — demonstrating the firm is ready to operate on submission?
  7. Has the firm used the FCA's Pre-Application Support Service (PASS), with points raised and responses recorded?
  8. For an MLR-registered firm: is there a gap analysis from the AML-registration operating model to full FSMA authorisation — governance, SM&CR, conduct, prudential, custody, resilience — rather than an assumption that registration evidence carries across?
  9. For a firm relying on a s.21 approver: is the promotions position through transition mapped — continued approver use if applied in the window, and pre-existing-contract-only promotions otherwise?
  10. For an overseas firm: is the UK-establishment and customer-access analysis done under FG26/7, including which entity applies and which overseas entities rely on its continuation rights?
  11. If relying on the transitional provision: are the FCA start/stop notifications made, counterparties notified, and new business demonstrably blocked?
  12. Post-authorisation: is the permission profile kept in line with activity — any new activity or token type preceded by perimeter analysis and, where needed, a VoP before launch?
  13. Post-authorisation: are regulatory returns submitted accurately and on time, with preparation for the supplementary questions the FCA is developing with firms?
Evidence to obtain & test
  • Perimeter mapping memo — activity-by-activity analysis against the nine activities and PS26/18.
  • Commencement-position note — saving / transitional / run-off, with dates.
  • Threshold Conditions self-assessment including group structure and close links.
  • Application project plan working back from 28 February 2027, with owners.
  • Regulatory business plan and projections, with board approval.
  • PASS meeting notes and action log.
  • MLR-to-FSMA gap analysis and remediation plan.
  • s.21 approver agreement and transition plan for promotions.
  • FG26/7 UK-establishment analysis.
  • FCA notifications and counterparty letters; new-business block evidence.
  • New-product / new-token approval log with perimeter sign-off.
  • Regulatory returns calendar and submission history.
26
Activity conduct rules — stablecoins, platforms, intermediaries, staking, lending
PS26/10 · PS26/11 · CRYPTO 2 · CRYPTO 5–10 · COBS
Conditional — set scoping—›
Qualifying criteria
Rules follow the activities selected at Q13Set by scoping Q13
Review questions
  1. Stablecoin issuance (CRYPTO 2): is the backing-asset pool composed within the permitted assets, held under statutory trust arrangements (no unallocated backing fund accounts), with any excess within the 5% limit and any intragroup custody within the permitted safeguards?
  2. Redemption: is redemption at par operationally deliverable within the required timelines, including how redemption requirements apply in the secondary market?
  3. Holder disclosures: are current and historical disclosures available to holders, and prospective holders made aware of their withdrawal rights?
  4. Operating a platform: are operating rules, access criteria, fair and orderly trading controls and conflicts arrangements (including any group dealing) documented and operating?
  5. Best execution (intermediaries): are there effective overarching execution arrangements — rather than transaction-by-transaction checks — using multiple venues for price checks, supported by periodic monitoring and post-trade analysis?
  6. Dealing as principal: are conflicts between own-account positions and client orders identified and managed, with pricing and spreads disclosed? (Principal dealers are outside the pre-trade transparency requirements.)
  7. Lending / borrowing: are the retail protections in place — enhanced disclosures, consent, appropriateness testing, record-keeping, over-collateralisation and negative balance protection — with any automatic collateral top-up limits applied to the firm?
  8. Staking: are disclosures, contractual terms and client consent in place, with records kept for all clients? Where auto-staking is offered, does consent satisfy the conditions and is annual notification given? Are liquid-staking record-keeping requirements applied where relevant?
  9. Are customer-facing processes aligned to the COBS provisions applied to cryptoasset firms by PS26/13 (communications, appropriateness, record-keeping)?
  10. Post-authorisation: is conduct-rule compliance tested through the compliance monitoring plan — sample testing of execution, disclosures, consent and appropriateness records?
Evidence to obtain & test
  • Activity-by-rule compliance matrix mapping each selected activity to its CRYPTO chapter.
  • Backing-asset policy, trust documentation, custody agreements and daily pool composition records.
  • Redemption policy and redemption-timeline test records.
  • Holder disclosure archive and withdrawal-rights notices.
  • Platform operating rules, access criteria and conflicts register.
  • Execution policy and periodic best-execution monitoring / post-trade analysis.
  • Principal-dealing conflicts policy and spread / pricing monitoring.
  • Lending / borrowing disclosures, consents, appropriateness records and collateral / negative-balance controls.
  • Staking terms, disclosures and consent records; annual auto-staking notifications.
  • Compliance monitoring results for conduct testing.
27
Admissions & disclosures and market abuse (A&D / MARC)
PS26/9 · CRYPTO 3 · CRYPTO 4
Conditional — set scoping—›
Qualifying criteria
A&D — offers and admissions to trading on UK QCATPsPlatforms, stablecoin issuers, and intermediaries dealing / arranging in admitted tokens
MARC — insider dealing, unlawful disclosure, manipulationAll firms trading or arranging trading in qualifying cryptoassets; conduct reached in or outside the UK
Large UK QCATP operatorsAdditional MARC obligations above the FCA threshold
Review questions
  1. Admissions: for each asset admitted, is due diligence performed against the admission criteria, a qualifying cryptoasset disclosure document (QCDD) in place (no fungibility exception), supplementary-disclosure triggers monitored and the digital token identifier standard applied?
  2. Platform market abuse systems: are there systems and procedures to detect and prevent insider dealing and manipulation, with suspicious activity reported and participation in industry-led information sharing?
  3. Large UK QCATP: if above the threshold, is on-chain monitoring in place within the (narrowed) required scope?
  4. Intermediaries: are the required notifications to UK QCATPs made, and are orders and transactions monitored for abuse?
  5. Issuer disclosure: is inside information identified and disclosed as required, with insider lists maintained?
  6. Does the firm's market abuse policy reflect the MARC definitions of inside information and legitimate market practices, with staff training and personal-dealing controls covering cryptoassets?
  7. Post-authorisation: are surveillance alerts reviewed and dispositioned within set timeframes, with calibration reviewed periodically? (The FCA is extending its penalty framework to MARC — CP26/19.)
Evidence to obtain & test
  • MARC market abuse policy and training records.
  • Admission due-diligence file and QCDD for a sample asset.
  • Platform surveillance configuration and suspicious-activity log.
  • QCATP notification records and order / transaction monitoring.
  • Inside-information disclosure log and insider lists.
  • Alert disposition MI and calibration review.
28
Safeguarding & client assets — CASS 17, CASS 16, CASS 7
PS26/10 · PS26/11 · CASS 16 · CASS 17 · CASS 7 · CASS 6 (RSICs)
Conditional — set scoping—›
Qualifying criteria
CASS 17 — client cryptoassets safeguarded by custodiansSafeguarding / arranging safeguarding; control-based application
CASS 16 — stablecoin backing assetsStablecoin issuers
CASS 7 — client money arising from or in connection with safeguardingCustodians (not stablecoin issuers)
Relevant specified investment cryptoassets (RSICs)Authorised as cryptoasset custodian but apply CASS 6 for now
Review questions
  1. Is it documented which CASS chapters apply to the business and why — including where control-based application brings arrangements into CASS 17?
  2. Are client cryptoassets held on trust (or within the targeted exceptions) and segregated, with ownership rights clear in client terms?
  3. Are records and reconciliations performed as required, with discrepancies escalated and resolved?
  4. Is private key management governed on the FCA's technology-agnostic basis — generation, storage, signing authority, access, recovery — with independent testing?
  5. If a settlement float is used, is it within the 2% limit and monitored?
  6. Where safeguarding is arranged with a third party, is the third-party custodian selected, appointed and monitored with documented due diligence?
  7. Is client money arising in connection with safeguarding handled under CASS 7?
  8. Are backing assets safeguarded under CASS 16?
  9. Post-authorisation: are CASS breaches recorded and notified, and is the CASS oversight function reporting to the board? (Resolution and distribution rules for failed custodians and issuers remain under FCA consultation.)
Evidence to obtain & test
  • CASS applicability note covering CASS 6 / 7 / 16 / 17.
  • Client terms on ownership and trust; segregation evidence.
  • Reconciliation records and break log.
  • Key-management policy and independent test report.
  • Third-party custodian DD and appointment files.
  • CASS 16 backing-asset safeguarding records.
  • CASS breach register and board reporting.
29
Crypto prudential — COREPRU & CRYPTOPRU
PS26/12 · COREPRU · CRYPTOPRU · GC26/4 · GC26/5
Conditional — set scoping—›
Qualifying criteria
Own funds requirement (OFR)Highest of PMR, FOR and K-factor requirement (KFR)
Crypto K-factorsInclude K-SII (stablecoin issuance, 1%), K-NCP (net cryptoasset position), K-CCD (counterparty credit default)
Threshold requirementsOFTR and LATR set through the overall risk assessment (COREPRU 7 / CRYPTOPRU 7)
Public disclosureRequired where FOR or KFR is the binding OFR component; not where PMR binds
Review questions
  1. Is the OFR calculated with the binding component identified, and the public disclosure obligation assessed on that basis?
  2. Is K-SII calculated at the 1% coefficient?
  3. For own-account positions: are assets that can be prudently valued and are admitted to a UK QCATP given the 40% net risk position (K-NCP) and 40% volatility adjustment (K-CCD), and are other cryptoassets deducted from capital with a 100% volatility adjustment?
  4. Is the overall risk assessment complete — harms, stress testing, wind-down planning — setting the OFTR and LATR, with regard to the FCA's non-Handbook guidance consultations (GC26/4, GC26/5)?
  5. Is there a costed, board-approved wind-down plan?
  6. For a MIFIDPRU investment firm adding crypto permissions: is the interaction between CRYPTOPRU and MIFIDPRU mapped?
  7. Post-authorisation: are own funds and liquid assets monitored against thresholds with early-warning indicators, and prudential returns filed?
Evidence to obtain & test
  • OFR calculation showing PMR, FOR and KFR with the binding component.
  • Overall risk assessment with OFTR and LATR.
  • Wind-down plan with board approval.
  • K-NCP / K-CCD workings with asset classification.
  • Capital and liquidity MI and returns history.
30
Consumer Duty, financial crime & operational resilience
PS26/13 · FG26/5 · FG26/6 · MLR 2017 · Travel Rule · SYSC
Conditional — set scoping—›
Qualifying criteria
Consumer Duty applied to cryptoasset firms (FG26/5)Firms with retail customers
Operational resilience (FG26/6)All crypto firms
AML / CTF — MLR 2017 obligations continue; separate MLR registration no longer needed once authorisedAll crypto firms (Financial Crime Guide updates under consultation)
Review questions
  1. Consumer Duty: are products and services assessed for price and value, target market, consumer understanding and support, in line with FG26/5 — with outcomes monitoring and board reporting?
  2. Financial crime: is the firm-wide AML risk assessment crypto-specific (unhosted wallets, anonymity-enhancing assets, high-risk jurisdictions, counterparty exposure), with blockchain analytics for transaction monitoring and wallet screening?
  3. Is the Travel Rule operating, including the approach to unhosted wallets and counterparties in jurisdictions without equivalent rules?
  4. Is sanctions screening applied to customers and wallet addresses, with an OFSI reporting route and an on-chain freezing procedure?
  5. Operational resilience: are important business services, impact tolerances and third-party dependencies (custody technology, cloud, analytics, liquidity providers) mapped and tested in line with FG26/6?
  6. Is there an incident-response plan covering loss or theft of cryptoassets, platform outage and chain events, with client communication and FCA notification?
  7. Post-authorisation: is the annual Consumer Duty board report produced, and are resilience scenario tests and AML reviews run on schedule?
Evidence to obtain & test
  • Fair value assessments and Consumer Duty outcomes MI.
  • Crypto-specific AML risk assessment and policies.
  • Blockchain-analytics configuration and dispositioned alerts sample.
  • Travel Rule procedure and sample transfer record.
  • Sanctions / wallet-screening records and freezing procedure.
  • Important business services mapping and scenario test results.
  • Incident-response plan including asset-loss scenarios.
  • Annual Consumer Duty board report and AML annual review.

Want a second pair of eyes on your answers?

Reg Advantage supports firms through Part 4A authorisation and runs ongoing compliance monitoring and testing — led by a former UK Head of Compliance with SMF16/17 experience.

Talk to James Lane